CHFI Storage Forensics and File System Analysis Practice Question
An analyst retrieves a forensic image of a hard drive and discovers that the size reported by the operating system is smaller than the actual physical capacity. The extra space is not accessible through standard partition tools. This hidden area is MOST likely:
⚠ Common exam trap
EC-Council often tests the distinction between HPA and DCO, where candidates confuse the ATA commands (SET MAX ADDRESS vs. DEVICE CONFIGURATION) and incorrectly assume DCO is the primary hidden area when the symptom is a reduced OS-reported size.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Host Protected Area
The Host Protected Area (HPA) is a region on a hard drive that is hidden from the operating system by using the ATA SET MAX ADDRESS command to reduce the reported capacity. This area is not accessible through standard partition tools because the OS sees only the reduced address space, making it ideal for storing forensic or diagnostic data. The analyst's observation of a smaller reported size than physical capacity directly matches HPA behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device Configuration Overlay
Why it's wrong here
Device Configuration Overlay (DCO) is indeed a hidden ATA region that can reduce the total addressable sectors, but it is not the answer here because the HPA is the specific area created with the Set Max Address command. DCO sits above the HPA and can itself hide the HPA from the OS, so forensic examiners must disable DCO before they can even access the HPA. Since the question asks about the hidden area configured via ATA commands that causes a difference between reported capacity and physical platter size, DCO is a separate overlay and therefore incorrect.
- ✓
Host Protected Area
Why this is correct
Host Protected Area (HPA) is the correct answer because it is a hidden region created using the ATA Set Max Address command, which makes the operating system see a smaller disk than the physical platter actually contains. This area cannot be accessed through normal OS commands and is frequently used to conceal data for forensic analysis or other purposes. When an analyst observes that the OS-reported capacity is less than the physical drive size, the HPA is exactly the hidden area responsible for that discrepancy.
- ✗
Volume slack
Why it's wrong here
Volume slack is the unused space at the end of a partition, extending from the last used file system cluster to the volume boundary, and it is not hidden from the operating system—the file system is aware of this space as part of the volume. It does not represent a reserved region beyond the last logical block address of the physical drive, which is what the question describes. Therefore, volume slack is incorrect because the capacity mismatch in the scenario points to a hardware-level hidden area like the HPA, not leftover space inside a partition.
- ✗
RAM slack
Why it's wrong here
RAM slack fills the gap between the end of a file’s logical data and the end of the sector that contains it, not the difference between the OS-reported capacity and the physical platter size. It is tempting because slack space is a common hidden data area, but it exists within allocated clusters, not as a reserved region beyond the last logical block address. RAM slack would be the correct choice if the question described unallocated space within a file’s final sector, not inaccessible capacity at the drive’s physical boundary.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
About these practice questions
This CHFI question is part of Courseiva's 205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.